Human risk program maturity
Human Risk Maturity Model
The Human Risk Matrix shows which behaviors create risk. This model shows how a security program matures against them, in five levels. A program starts with compliance training, then learns to manage behavior: it maps the threats it faces to the behaviors that drive them, trains on those behaviors, measures them, and drives risky behavior down over time. The last step is the hardest: finding the rare, high-fidelity signals of malicious intent hidden in the noise, where insider-threat and counter-intelligence work sits.
Not every organization can build the same capability. Each level lists what it looks like for a small business, a mid-size company, and an enterprise. Each size has a ceiling: small stops at Level 3, mid-size at Level 4, enterprise at Level 5. Above the ceiling, you transfer, outsource, or accept the risk.
- L1Compliance Awareness
- L2Just-in-Time Training
- L3Threat-Informed Risk Management
- L4Insider-Threat Detection
- L5Proactive Human Risk Program
The five levels
- Level 1
Compliance Awareness
Training is a box to check.
A baseline program that delivers required security training to everyone on a set schedule, to satisfy compliance. It produces a trained workforce on paper and the completion records an audit needs. It does not change behavior or reduce real risk, and success is measured by who finished rather than what changed.
- Focus:
- Educate
- Signals:
- Training completion records.
- Tooling:
- Awareness or SAT platform, email filtering, antivirus, MFA.
- Blind spot:
- It tracks attendance, not risk. It cannot show whether anyone is safer.
By size
- Small
- An off-the-shelf training tool with automatic enrollment, run part time by IT or an MSP.
- Mid-size
- A security team runs the program in an LMS and reports completion to risk or audit.
- Enterprise
- A dedicated team runs an enterprise LMS with audited completion and policy sign-off.
Next. Deliver training in context when a risky action happens, and measure behavior.
- Level 2
Just-in-Time Training
Coach people at the moment of risk.
The program moves from scheduled training to coaching at the point of risk. It detects risky actions as they happen and delivers targeted guidance and a corrective step in the moment. It delivers fewer everyday mistakes and faster correction, but does not yet build a lasting picture of each person's risk.
- Focus:
- Educate, Intervene
- Signals:
- Live triggers from email, DLP, the browser, and endpoints. Each is handled on its own.
- Tooling:
- Human-risk platform nudges, email security, DLP.
- Blind spot:
- It reacts, but it has no memory. It cannot tell a repeat offender from a one-off, or coach based on history.
By size
- Small
- Built-in warnings from the tools already in use, plus a platform's in-the-moment tips.
- Mid-size
- Security sets up contextual prompts across email and DLP, each with a way to report.
- Enterprise
- The awareness team ties just-in-time coaching to the wider program and tunes it by role.
Next. Map the threats you face to the behaviors that drive them, and measure those behaviors over time.
- Level 3
Threat-Informed Risk Management
Manage the behaviors that drive risk.
The program manages human risk through behavior. It maps the threats and risks it faces to the behaviors that drive them, using the Human Risk Matrix, then trains on those behaviors, measures them, and indexes on their reduction over time. It delivers a clear view of which behaviors matter most and evidence that risky behavior is falling.
- Focus:
- Educate, Evaluate, Monitor
- Signals:
- Behavioral data from UEBA, DLP, identity, and access logs, mapped to the matrix, plus simulation results.
- Tooling:
- Human-risk platform, UEBA, DLP, phishing simulation.
- Counter-intel:
- Controlled testing begins here, a first overlap with counter-intelligence method.
- Blind spot:
- It sees single behaviors, not the pattern that signals intent. A determined insider hides in normal noise.
By size
- Small(ceiling)
- One human-risk platform tracks behavior, maps it to the matrix, and assigns targeted training. The owner reviews a monthly dashboard. This is a small business's ceiling.
- Mid-size
- Security feeds UEBA, DLP, and identity logs into a matrix-mapped platform and runs simulations.
- Enterprise
- A human-risk team runs integrated telemetry, an ongoing simulation program, and standing controlled tests.
Next. Move from reducing common risky behavior to finding the rare signal that points to malicious intent.
- Level 4
Insider-Threat Detection
Watch for intent, not just error.
With everyday risky behavior measured and falling, the program shifts to finding the needle in the haystack: the rare, high-fidelity signals that point to malicious intent rather than a mistake. It correlates behavior across sources to surface deliberate acts such as data theft, sabotage, or disabling controls, and runs an insider-threat process to investigate and respond. It delivers detection of the few malicious actors hidden in the noise, using counter-intelligence method within security operations.
- Focus:
- Monitor, Intervene
- Signals:
- Correlated data from the SOC and identity, DLP, and endpoint tools, plus HR context.
- Tooling:
- SIEM, EDR, identity analytics, insider-threat case management.
- Counter-intel:
- Detection borrows counter-intelligence methods to spot a witting insider before they act.
- Blind spot:
- It works case by case. It does not yet deter or disrupt a deliberate threat, and it still trails the adversary.
By size
- Mid-size(ceiling)
- Managed detection and platform alerts feed a small group from IT, HR, and legal. External investigators are on call. This is a mid-size company's ceiling.
- Enterprise
- A dedicated insider-threat team with its own analysts, monitoring, and case management.
Next. Move from detection to investigation, disruption, and steady adaptation.
- Level 5
Proactive Human Risk Program
North starA program that learns and gets ahead of risk.
A program that learns and improves. It runs continuous detection, response, and threat intelligence, and feeds every outcome back to re-tune controls and training. It investigates and disrupts deliberate insider threats rather than only detecting them. It delivers a defense that stays ahead of a changing threat, reached by few organizations.
- Focus:
- Educate, Evaluate, Monitor, Intervene
- Signals:
- Behavior, telemetry, threat intelligence, and incident outcomes, used to reset priorities continuously.
- Tooling:
- Detection and response, threat intel, automation, case management.
- Counter-intel:
- Operational counter-intelligence is one capability here, to investigate and disrupt recruitment.
- Blind spot:
- It needs resources and authority that only the largest organizations have.
By size
- Enterprise
- Continuous detection and response, threat hunting, and automation, with a standing counter-intelligence capability for investigations and law-enforcement work.
Where are you today?
Pick your organization size and answer the questions. We’ll show your level today and what to do next.
1Is everyone assigned recurring security training, with completion tracked for compliance?
2Do risky actions trigger an in-the-moment warning or nudge for the user?
3Does a platform track behavior against the matrix and assign targeted training you review?
Not yet at Level 1
Do next, to reach Level 1: Establish Level 1 — Compliance Awareness.